From: Adam B. <ada...@gm...> - 2019-10-26 08:49:39
|
Hi Ravneet Firstly, did you realise the latest official release is 2.7.1? 2.7.2 beta should also be soon. 2.5.3 is quite old. 2.7.1 and 2.7.2 include a number of specifically security fixes, since that seems to be the main driver for yourselves. I imagine at least some of the fixes you've been applying have already been applied to the current dev version. If you have made patches that haven't otherwise been picked up, it would be great if you could contribute them back, going through the usual review process, of course. That would also mean minimal merge effort to you when they were in the trunk. On end of life. The informal consensus is that as there isn't a Jython 3.x yet, it would be unreasonable to make Jython 2.x EOL at the same date as CPython 2.x, and Jython 2.x will continue well into 2020. The core Jython devs and the PSF are trying to get a clearer statement on dates together that both can be fairly happy with. Cheers Adam On Fri, 25 Oct 2019 at 23:55, Ravneet Singh <rav...@al...> wrote: > Hi Team > > > > We are using Jython 2.5.3, and those Jython libraries contains Python > files also. Now for any security vulnerability reported in Python 2.X , we > had been referring the solution from python.org website and updating > those code files in the Jython libraries. Now since Python 2.X is going End > Of Life as mentioned by python.org from Jan 2020, then we have few > questions here: > > 1. How can we get the security fixes for the security issues/CVEs > reported in python 2.X files which are also used in Jython library. > 2. And, will jython.org would be providing the security fixes for the > security issues/CVEs reported in Python 2.X . > 3. And, when will the Jython 3 corresponding to Python 3.X getting > released. Is there any proposed date for the same. > > > > Apart from this, any suggestion from your side for users of Jython 2.X > taking in view that Python 2 is going End of Life. > > > > Thanks > > Ravneet Singh > ===================================================== > Please refer to https://northamerica.altran.com/email-disclaimer > for important disclosures regarding this electronic communication. > ===================================================== > _______________________________________________ > Jython-dev mailing list > Jyt...@li... > https://lists.sourceforge.net/lists/listinfo/jython-dev > |